CVE · Medium

CVE-2021-24568 — AddToAny Share Buttons [add-to-any] < 1.7.46

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24568 AddToAny Share Buttons [add-to-any] < 1.7.46 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.7.46 1.7.46 2021-08-09

CVE-2021-24568

The AddToAny Share Buttons plugin versions prior to 1.7.46 contain a Cross-Site Scripting vulnerability in its Sharing Header setting. The plugin fails to properly sanitize this setting before displaying it on the frontend, enabling administrators and other high-privilege users to inject malicious scripts even in environments where the unfiltered_html capability has been restricted. This flaw allows authenticated attackers with sufficient permissions to execute arbitrary JavaScript in the context of the website.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.